In case you haven't already seen the video, the BBC decided to do a little investigation into how easy it was to acquire, use and deploy a small botnet against a particular web site for a segment on their tech show Click.

Here's what they uncovered:





So, the Click investigators managed to DDoS a honeypot web site with just sixty-odd computers' worth of traffic. (Botnet owners must be loving all these new DSL packages with high-speed upload.) Before self-destructing the network, they also (very sensibly, in my opinion) changed the background image of all infected botnet hosts. The image contained had a detailed description of how that machine was compromised, along with a link to a special page on the BBC Click web site which explained how to go about securing the system.

Personally, I think they did the Internet a service - unfortunately this comes at a time when everybody is scrutinising everything the Beeb is doing, and they've been in the spotlight a little too much recently. Some are harping on about how this was a breach of the law (and with a rigid interpretation of the Computer Misuse Act, it most definitely was); we have people like Graham Cluley, the regular Sophos spokesperson, offering the anti-virus manufacturer's slightly condescending take on events. Others are also debating the legality - Click's producers have claimed that as there was no malicious intent behind their actions, they didn't breach the Law, some are pointing out that technically, the Law has been broken irrespective of intent. Struan Roberrtson from Pinsent Masons pointed out that;


"The Act requires that a computer has been made to perform a function with intent to secure access to any program or data on the computer," he said. "Using the botnet to send an email is likely to satisfy that requirement. It also requires that the access is unauthorized — which the BBC appears to acknowledge.

"It does not matter that the BBC’s intent was not criminal or that someone else created the botnet in the first place." Still, Robertson said prosecution was unlikely because the exercise apparently did no harm and "probably did prompt many people to improve their security." The BBC responded that there was 'a powerful public interest in demonstrating the ease with which such malware can be obtained and used,' and that the network "has strict editorial guidelines for this type of investigation, which were followed to the letter."


I fall in line with the latter way of thinking on this - the BBC mention that they consulted their own lawyers before conducting this experiment so they must feel they have a fairly solid case for avoiding penalty. I suspect their culpability is limited as many thousands of the machines were most likely situated outside of the United Kingdom, bringing the scope and geographical constraints of our lovely British law into question. (Without extraditing the entire upper management of the BBC, I suspect there's little way the Corporation could be tried in a court of law for what they have done overseas).

More importantly, are the rest of us justified, as responsible netizens (as many of us claim to be, or would at least like to believe), in the belief that we can criticise the BBC's actions and call them out for dirty tricks here? For some of their past actions, maybe; this time: no. Personally, I think they've done the Internet a service. Not only have they taken a (small) botnet out of action, but they've helped illustrate just how easy it is to acquire a pool of compromised resources and hammer a web site into submission.

As a few more clueful people have observed, what Click unfortunately didn't spend enough time highlighting (probably due to time constraints) is the ease with which the true malicious users seem to be able to avoid getting caught when buying and selling access to these botnets. There must be a large amount of shady transactions taking place for unnamed or suspect items - and Internet payment services are effectively allowing these to happen. Why can't e-money services like PayPal watch for, and flag, transactions which might be related to payment for these kinds of nefarious darknet services?

Update: the BBC responded shortly after with a press release, along with a feature from Mark Perrow which fleshes out their reasoning and underlying motivation for the investigation on their Editors' Blog. The short statement is as follows:

"There is a powerful public interest in demonstrating the ease with which such malware can be obtained and used; how it can be deployed on thousands of PCs without the owners even knowing it is there; and its power to send spam email or attack other websites undetected. This will help computer users realise the importance and value of using basic security techniques to defend their PCs from such attacks.


The BBC has strict editorial guidelines for this type of investigation which were followed to the letter. At no stage was any other data other than the IP address used. We believe that as a result of the investigation, computer users around the world are now better informed of the importance and value of using basic security techniques to defend their PCs from attacks."




I still think this was a well-considered and justified insight into the underbelly of the interwebs, and if it raised peoples' awareness (and helped a few thousand people secure their machines) then surely the BBC has done the world a small favour? This invokes consideration of the classic White Hat / Grey Hat / Black Hat issue... Would you do something borderline (or completely) illegal if it was morally or ethically justified - or in the interest of the common good - in the long run? I'm not sure if I would (but then again, I can't hide behind a Corporation!)

I'd like to issue a full and categorical denial of this. We've never had any request for such data by anyone, and if we did we wouldn't consent to it.

Of course we work with the major labels and provide them with broad statistics, as we would with any other label, but we'd never personally identify our users to a third party - that goes against everything we stand for.

As far as I'm concerned Techcrunch have made this whole story up.


A response from Russ, an employee at Last.fm, over allegations made by TechCrunch recently that Last.fm had essentially handed over massive chunks of private user data to the RIAA so they could find out who was listening to (and therefore, most probably sharing and/or downloading) prerelease leaks of the new U2 album.

Who's telling the truth? As long as no British laws were broken, I don't really care, and I'm sure we'll find out soon enough anyway once the FUD has dissipated. (I'm sure the RIAA and U2's manager are conveniently forgiving Universal Australia for 'accidentally' making U2's latest album available for digital download via their web site a few weeks before its official launch... One rule for them, another for us, just as usual.

To be honest, I'm far more interested at the moment in an announcement from Indian scientists who say they've developed a method of using enzymes to take carbon dioxide emissions and convert them into things like cement and other useful building materials. How cool is that!


Much love to the fabulously geeky xkcd, as always. Buy some of their stuff and support Randall, the merch is as witty (and enduring) as his comics. :) (If you like, buy some for me!)

So good, even I want one! And I hate Macs!


The CNN/Facebook collaboration was a remarkable look into the way that people are moving from regular, directed TV to more 'raw' news consumption - and readily commenting as it happens.

The CNN.com Live with Facebook page, which is offering the Flash stream of CNN with a Facebook 'representative sample' of realtime status comments from other viewers, looked like this a little earlier after you loaded it:






However, a little earlier, the "Connect or Sign Up for Facebook to discuss this historic inauguration" text changed to this rather more amusing version:




... 'i love my little elf boy'? Sounds like someone's found a back door to Facebook's infrastructure ;) What worries me is whether this is a merely cosmetic hack or whether this also indicates that deeper, more important sections of Facebook's infrastructure are theoretically available to view by more unscrupulous individuals. Are my personal details still safe, having logged into Facebook via that (authentic) CNN page earlier? Is it as simple (but still worrying) as an admin's details been compromised?

People need to watch their Facebook accounts for the next few days, juuuust in case.

On a lighter note, this day was certainly one for record breaking - not only does the USA have its first African-American President, but Mashable reports the statistics announced by CNN earlier:

"The stats released, as of noon ET:

  1. There were 200,000+ status
    updates through the Facebook integration on CNN.com
  2. At that time, 3,000 people commented on the Facebook CNN feed per minute
  3. Obama’s Facebook Fan Page has more than 4 million fans and in
    excess of 500,000 wall posts

As of 11.45am, CNN:

  • had served 13.9 million live video streams globally since 6am
  • had broken its all time total daily streaming record (from Election Day) of 5.3 million live streams

Impressive numbers indeed."

I'll say! And, in traditional British manner, our BBC live stream handily broke down just after Obama's inaugural address - and only began to work again (with a low-key announcement on the BBC News inauguration coverage page) at around quarter past six UK time. Never mind, Blitz Spirit and all that!

If you have kids who always sit on your laptop while you're trying to work, you'll appreciate the distraction value of being able to shuffle them over to another PC and put the official CBeebies web stream on. (my old boss suffered from this 'affliction', but his daughter is quite, quite happy about the whole thing.)

However, many others bemoaned the lack of the main BBC channels, as first BBC Three, then Four, were first rolled out as a trial after BBC News' move to Flash streaming (followed by CBeebies and a couple of other channels). However, on New Years' Eve, they finally made BBC One and BBC Two's web streams public - with a bbc.co.uk front page promo for the New Year's Eve and Jools Holland's Hootenanny shows, finally available as online streams. Woohoo. The quality's not spectacular, being pipped by TVCatchup - but the fact that it's being run by the BBC means that its future is almost certainly secured, and no doubt the quality will increase, mirroring the subsequent "High Quality" stream introduction for iPlayer on-demand programming.

However, given things like the ISPs' unwillingness to have to cough up for all this sudden upsurge in Internet usage, combined with Anthony Rose's recent, somewhat misguided suggestion that ISPs should consider options such as charging an extra monthly fee for high quality stream access... Well, it doesn't exactly inspire unbridled hope, but there's still scope for change.

(A little aside by way of explanation: Mr. Rose's suggestion to ISPs was that they consider charging an extra fee, maybe upwards of £10 a month on top of the customer's existing service charge, in order to offset the cost of all the bandwidth consumed by viewing iPlayer - and other online video - content. However, vocal opponents of this idea have argued that customers are already paying for access to iPlayer, both in the form of their TV Licence and their standard monthly charge. If ISPs begin to charge extra for access to the High Quality streams, it's effectively a two-tiered Internet via the back door, and the end of net neutrality while we're at it as well. Rather grim, and I'm completely against the concept of charging extra for something we should already have full access to. Happily, I'm with Be* once again for my broadband, after moving to Virgin Media last year from Be* (due to my old house's awful phone line - the main problem for ADSL2+ customers - before VM introduced the doubled speeds, STM and P2P throttling... And unlike Virgin up-shit-creek Media, Be* aren't frustratingly backward with tiered access or restrictive bandwidth caps.

Back on point now...)

Anyway, my point of view in a nutshell: if ISPs can't afford to offer the bandwidth customers are paying for as part of their package, they should price their packages more realistically or lower the allowances. Surely they've learnt something from the mistakes the Banking sector have made over the past decade?

That aside, official online streaming of all the main channels is a welcome step in the right direction, as people like me (who've paid for a TV Licence but don't have a TV at the moment) can finally watch all the BBC channels without having to rely on grey-area platforms like the reinvented TVCatchup (which is still albeit slightly better quality, although I'm not sure how long it'll last) or Zattoo (which is so-so in terms of quality, but has some other interesting channels). The fact that it's Flash streaming means that it's not fully accessible yet across every single OS, and is not available to watch on all devices - but hopefully MP4 or H.264 streaming in a regular MKV or MP4 wrapper will be available once they sort out the rights issues (I believe they're still forced to use Flash due to DRM and geolocation restrictions). Anyway, if you want to check out the streams for yourself (UK viewers only, unfortunately), here are some links I'm sure you'll enjoy:

BBC One: http://www.bbc.co.uk/bbcone/watchlive/
BBC Two: http://www.bbc.co.uk/bbctwo/watchlive/
BBC Three: http://www.bbc.co.uk/bbcthree/livearena/ (from 7pm daily)
BBC Four: http://www.bbc.co.uk/bbcfour/watchlive/
CBBC: http://www.bbc.co.uk/cbbc/watch/cbbclive/ (7am to 7pm daily)
CBeebies: http://www.bbc.co.uk/cbeebies/watch/cbeebieslive.shtml (6am to 7pm daily)
BBC News: http://news.bbc.co.uk/1/hi/uk/7459669.stm
BBC Parliament: http://www.bbc.co.uk/iplayer/playlive/bbc_parliament/

Now, the interesting thing to note is that BBC Parliament streams from the /iplayer site. So, I decided to delve a bit - if you substitute bbc_parliament for bbc_one ... You get the BBC One stream... except those streams don't work at the moment. The same goes for "bbc_two", "bbc_three", "bbc_four", but "cbeebies" and "cbbc" do work. "bbc_news24" gives you the BBC News channel - finally, an easier to remember link than that stupidly long news.bbc.co.uk link! And, although "bbc_one" doesn't work, "bbc_one_england" does, and the same goes for "bbc_two_england". Do you smell forthcoming regional variations? All the channels' streaming pages also show the Now and Next information (and this goes for the channels' respective iPlayer live stream pages and their Watch Live pages on their respective minisites). Very handy.

Oh, and BBC Alba's also available to watch online - but as I can't understand it (it's for the Scots), I don't really care. ;)

Direct links to all of the available live streams in the /iplayer style (which I vastly prefer over the minisite-designed pages) are available via the "Watch LIVE" links at the top right of each page once you click onto the main channels. To do this, go to bbc.co.uk/iplayer and click on one of the TV channels' names in the "TV" pane - or click on TV Channels at the top of the page then click on the channel's name. Once you're there, and the channel is currently streaming, you can click the 'Watch LIVE' link. Simplicity itself (although I'd prefer a single click from the front /iplayer page to get to it, but never mind).

This is a far cry from the first public implementation of iPlayer, isn't it? Whilst not every single programme is available to view online (again, due to rights restrictions - mostly films and older programmes I would expect are not available to simulcast online, as the CBeebies "information for adults" page cryptically explains). Who would've thought that we'd still be watching Flash streams in 2009? I thought we would've been at H.264 inside an MP4 wrapper which I could stream in VLC, Media Player Classic or (shock horror) Windows Media Player, but we'll get there eventually. Hell, even a WMP stream which I could stream over my smartphone's 3G connection would be a better option, but hopefully that's in the pipeline. For the moment, Flash streams are a good warm-up for the next development :) (which hopefully should be with us soon, fingers and toes crossed on that one everybody).


Oh, and welcome to 2009 everyone! May your tech and gadget purchases be many and wonderful and without buyer's remorse.


 

Copyright 2006 onwards Christopher Woods. Some Rights Reserved.
ITU uses a (highly) modified version of the K2 theme by GeckoandFly,
originally Bloggerised by Blogcrowds. Credit where credit's due. :)


Into The Unknown is licenced under a Creative Commons License.
(Attribution-Share Alike 2.0 UK: England & Wales, Some Rights Reserved).

Creative Commons License